OpenAI has confirmed Zero Data Retention (ZDR) as a standing policy for eligible API customers, meaning no prompts, completions, or model inputs are stored after a request completes. This applies to frontier models including GPT-4o and o-series models. Enterprise and API customers who qualify get this by default, no negotiation required.
The more consequential announcement is Private Safety Processing, a forthcoming architecture that runs safety checks on inputs without exposing that data to OpenAI's systems. This matters because it dissolves the core tension that has pushed regulated industries, legal firms, and healthcare operators away from cloud AI: you cannot run safety filters without seeing the data, until now. The technical mechanism behind how OpenAI separates the safety signal from the content payload is the reason to read the full post.
If Private Safety Processing delivers on its design, it redraws the boundary for enterprise AI adoption in compliance-heavy sectors. The next question is audit verification: how does a customer confirm ZDR is actually happening, and what independent attestation exists. OpenAI addresses this partially, but the gaps in third-party verification are worth scrutinizing in the original.
[READ ORIGINAL →]